Windows Vista
Kaspersky Lab believes that Vista's security may not be as effective as promised
R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Windows Vista security under fire

Kaspersky questions platform's ability to fight off malware

Robert Jaques, vnunet.com 30 Jan 2007
ADVERTISEMENT

Microsoft's Windows Vista is "unlikely to deliver long-term robust security protection", an IT security vendor claimed today.

An article published by Kaspersky Lab questioned whether the current security functions implemented in Vista will be effective.

The report, written by Kaspersky virus analyst Alisa Shevchenko, examined the key security aspects of Vista, including User Account Control, PatchGuard and Internet Explorer 7.

Vista's User Account Control ensures that any user, including the Administrator, has minimal rights, and that any 'suspicious' activity results in either a request for confirmation or a request to enter a password.

However, Shevchenko believes that a large number of harmless actions can be classed as 'suspicious', even if they turn out not to be malicious.

Alerting the user to each of these is likely to cause such a high volume of alerts that the user will either disable the feature or enter the Administrator password.

Shevchenko also claimed that "any type of protection can be evaded, and because of this, the advantages provided by this new layer of defence are conditional, and as practice shows, temporary".

He went on to claim that PatchGuard, which monitors modifications to the core system, can be evaded or disabled.

Shevchenko also questioned PatchGuard's protection against root-kits as it only offers protection against certain types of root-kit, and not all.

"Vista is undoubtedly more secure than previous Microsoft operating systems. And a system which is configured in such a way that everything is blocked except for access to designated sites could be regarded as being absolutely secure," said the report.

"However, the majority of users will find the significant restrictions on actions which effectively sterilise the system unacceptable, just as the constant requests to confirm or enter a password for an action which the system defines as being 'potentially dangerous'.

"And it is at this point that the 'almost totally secure' system is transformed in to a 'more vulnerable' system'."


All Operating Systems

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
United Kingdom | Advent Computer Training
Are you stuck in a dead end job? Do you want to take control of your salary, life and career? Advent IT and computer training offers advanced, professional training and helps you find the right ... more >
Newcastle upon Tyne, United Kingdom | NCFE
Information Services Manager - £37,626 - £50,633 - Newcastle Upon Tyne   Information Services Manager, (IT Manager) Newcastle Upon Tyne, Times Top 100 company, City Centre Location.  We're looking for an experienced IT Manager/professional who ... more >
London, United Kingdom | BP
Technical Architect - £ Competitive - LondonAbout BP Our business is the exploration, production, refining, trading and distribution of energy. This is what we do, and we do it on a truly global scale. With ... more >
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
CMS Engineer - Welwyn Garden CityWho's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at just under ... more >
More job opportunities